This page describes how the Visalaw.ai MCP connector for Claude handles data, as a supplement to Visalaw's general Privacy Policy. Where the two differ, this page governs data handling specific to the connector; the general policy governs everything else about your Visalaw.ai account.
What this connector does
The connector gives Claude read-only access to Visalaw.ai's immigration law research tools — library search, statute/regulation lookup, case law search, and document retrieval — on behalf of a signed-in Visalaw.ai user, scoped to that user's organization.
Data collection and use
Authentication data. We store a SHA-256 hash of your OAuth access token for fast lookup, alongside your Visalaw.ai user ID, organization ID, granted scope, and token expiry. We also store an encrypted copy of the token itself (using the same encryption Visalaw.ai applies to its own API keys), which is recoverable by Visalaw.ai and used to support our existing permissions system. We do not store your Visalaw.ai password or Supabase session token.
Tool call data. Each tool call is processed to return results. Server-side we log only the name of the tool invoked together with your user and organization ID, for security and abuse monitoring. The arguments you pass — search queries, citations, document IDs — are not written to our logs.
No model training. Consistent with our general privacy policy, queries and content returned through this connector are not used to train any AI models.
Third-party sharing
CourtListener. The search_case_law tool sends your search query (case name, topic, or legal question, plus any jurisdiction/date filters) to CourtListener, a third-party legal research API, to retrieve case law. No Visalaw.ai account information is sent to CourtListener.
We do not sell personal information, consistent with our general privacy policy.
We do not share connector usage data with your employer or any other party beyond what's described here and in the general privacy policy.
Data retention
- Access tokens expire automatically after 90 days, and the stored token record is deleted at expiry.
- Disconnecting the connector in Claude stops Claude from using it. To end the token on our side, contact us; otherwise it expires after 90 days.
- Tool-call logs are retained for 30 days, then deleted automatically.
Your rights
You can request deletion of your data, including connector-related data, at any time. Consistent with our general privacy policy, we will comply within 30 days of such a request.
Contact
Questions about this policy: support@visalaw.ai, or see the contact details in our general Privacy Policy.
Visalaw Ventures, Inc. — 1028 Oakhaven Road, Memphis, TN 38119




